Intel

AIKIDO-2026-260229

apache-airflow-providers-keycloak is vulnerable to Reliance on Cookies without Validation and Integrity Checking

Reliance on Cookies without Validation and Integrity CheckingCVE-2026-76186 Published 2 days ago

91

Critical Risk

This Affects:

PYTHONapache-airflow-providers-keycloak
0.0.1 - 0.9.0
Fixed in 0.10.0
Are you affected? Scan for Free

TL;DR

From Airflow 3.3, the Keycloak auth manager derives a user's identity from a cookie value without checking that Keycloak signed the cookie. A caller who can set that cookie can present an arbitrary Keycloak identity, and Airflow grants access under it. The fix validates the cookie's signature before trusting the identity it carries.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the Keycloak auth manager with cookies reaching Airflow from an untrusted browser context.

Background info

apache-airflow-providers-keycloak is vulnerable to Reliance on Cookies without Validation and Integrity Checking in versions 0.0.1 - 0.9.0.

How to fix this

Upgrade the apache-airflow-providers-keycloak library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform